CVE-2026-8461Patch

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 32 mentions across 12 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 25 signals
  • Disclosure: 10 classified signals
  • Peaked 9d ago at 9 mentions (2026-06-24); latest day: 2
  • 32 total mentions across 12 days

Deep dive

Activity timeline32 mentions / 12d
02579Mentions · 2026-06-22: 3Mentions · 2026-06-23: 6Mentions · 2026-06-24: 9Mentions · 2026-06-25: 3Mentions · 2026-06-26: 3Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-03: 1Mentions · 2026-07-07: 1Mentions · 2026-07-16: 1Mentions · 2026-07-27: 1Mentions · 2026-08-14: 2PoC Mentioned / Linked · 2026-06-22: 1PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-24: 2PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-26: 2PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-08-14: 1Exploit Tool / Code · 2026-06-22: 1Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-08-14: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-03: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-23: 4Patch / Workaround · 2026-06-24: 3Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 2Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-06-22: 3Technical Details · 2026-06-23: 6Technical Details · 2026-06-24: 5Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 3Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-27: 1Technical Details · 2026-08-14: 106-2206-2306-2406-2506-2606-3007-0107-0307-0707-1607-2708-14
Signal classification6 categories
Patch
1237.5%
Disclosure
1031.3%
Exploit
412.5%
General
39.4%
PoC
26.3%
Active Exploitation
13.1%
Referenced assets29 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-223
Disclosure1Exploit1Patch1
2026-06-236
Disclosure2Patch4
2026-06-249
Disclosure4General2Patch3
2026-06-253
General1Patch1PoC1
2026-06-263
Exploit1Patch1PoC1
2026-06-301
Disclosure1
2026-07-011
Patch1
2026-07-031
Active Exploitation1
2026-07-071
Exploit1
2026-07-161
Patch1
2026-07-271
Disclosure1
2026-08-142
Disclosure1Exploit1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-8461: "PixelSmash" FFmpeg MagicYUV Heap OOB Write PoC Published: June 24th, 2026 PoC: https://github.com/Y5neKO/CVE-2026-8461-EXP https://t.co/oKIYoRR1EU

    Post summary

    A proof‑of‑concept for CVE-2026-8461 targeting an FFmpeg MagicYUV heap out‑of‑bounds write has been published, but no active exploitation, patch, or false‑positive claim is mentioned.

    0141552013.0K
    226.8K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    Un fichier vidéo de 50 Ko déposé par Sonarr/Radarr, scanné par Jellyfin, et c'est un RCE sans aucune action user. PixelSmash (CVE-2026-8461) frappe FFmpeg, donc tout l'écosystème : Kodi, Emby, OBS, Nextcloud… Correctif : FFmpeg 8.1.2. 👇 https://www.it-connect.fr/pixelsmash-une-faille-ffmpeg-expose-jellyfin-au-rce/ #cybersecurite https://t.co/SHJETvnAak

    Post summary

    A 50‑KB video file triggers an RCE in FFmpeg (CVE‑2026‑8461), impacting multiple media platforms; the issue is fixed by upgrading to FFmpeg 8.1.2.

    01102722.4K
    11.6K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    General

    Discover the critical PixelSmash vulnerability in FFmpeg. Learn how CVE-2026-8461 enables code execution and how to protect your media servers today. #PixelSmash #FFmpeg #CyberSecurity #Vulnerability #MediaServer https://meterpreter.org/ffmpeg-pixelsmash-vulnerability https://t.co/48KB6kB9OR

    Post summary

    The text announces the discovery of CVE-2026-8461, describing it as a critical code‑execution flaw in FFmpeg and points to a link for a guide on protection, but provides no concrete PoC, exploit code, or patch details.

    01073799
    12.8K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #AppSec #Threat_Research PixelSmash - Critical FFmpeg Vulnerability https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons // CVE-2026-8461 - critical vulnerability in FFmpeg's MagicYUV decoder leads to RCE via a crafted media file Triage alerts simple with: http://www.cyberpocket.org/

    Post summary

    A critical RCE vulnerability (CVE-2026-8461) in FFmpeg's MagicYUV decoder is disclosed, allowing attackers to craft media files that trigger remote code execution, but no exploit code or active exploitation evidence is reported.

    02052476
    3.4K followersView on X
  • JFrog@jfrog
    Disclosure

    🚨Weaponized media files! JFrog has uncovered "PixelSmash" (CVE-2026-8461), a high-severity flaw in FFmpeg's MagicYUV decoder (CVSS 8.8). 🛑 📦 By simply uploading a crafted 50 KB video, researchers achieved reliable RCE on Jellyfin and Nextcloud, and triggered immediate DoS crashes across mpv, Kodi, OBS, and vLLM AI pipelines. 📉 🛡️ See if you're exposed: https://bit.ly/4eHQD3t

    Post summary

    The post announces the discovery of a high‑severity CVE (CVE-2026-8461) in FFmpeg's MagicYUV decoder, detailing its exploitability via a crafted video that enables remote code execution and causes denial‑of‑service in several media applications.

    14030376
    23.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    FFmpegでPixelSmash脆弱性(CVE-2026-8461)が修正。libavcodecのMagicYUVにおけるヒープ境界外書き込みで、CVSSスコア8.8。遠隔コード実行にはASLRの無効化か別脆弱性との連鎖による突破が必要。 https://www.bleepingcomputer.com/news/security/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder/

    Post summary

    CVE‑2026‑8461, a heap‑boundary overflow in FFmpeg’s MagicYUV, has been fixed with a patch; the article provides technical details but no PoC or active exploitation evidence.

    000611.2K
    7.7K followersView on X
  • あおいん | 時事&シール沼&ご当地旅行@AoinRoom
    Patch

    メモφ(・ω・`) - FFmpeg自体は2026年5月時点で「クリーン・安全」と判定されている(オープンソースで用途も合法) - Homebrew経由のインストールも安全とされている - ただし最近、特定の動画コーデック(MagicYUV)に深刻な脆弱性(CVE-2026-8461、深刻度8.8/10)が見つかり、バージョン8.1.2で修正済み - 今からHomebrewでインストールすれば最新版(修正済み)が入るので、この脆弱性の影響は受けない - リスクは「動画編集ソフトが古いFFmpegを内蔵したまま更新しない」場合に出るもので、単体でインストールして自分で使う分には問題ない

    Post summary

    CVE‑2026‑8461, a severe vulnerability in the MagicYUV codec, has been fixed in FFmpeg version 8.1.2; installing via Homebrew ensures the patched version, mitigating the risk.

    10020166
    2.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🚨 FFmpeg MagicYUV decoder'ında kritik heap OOB write açığı (CVE-2026-8461 — PixelSmash) için PoC exploit yayınlandı: https://github.com/Y5neKO/CVE-2026-8461-EXP https://t.co/DETQpLN67F

    Post summary

    A tested PoC exploit for CVE‑2026‑8461, a critical heap OOB write in FFmpeg’s MagicYUV decoder, has been posted on GitHub, demonstrating exploitability but without evidence of real‑world use.

    00030251
    1.7K followersView on X
  • navanem@navanem
    Disclosure

    FFmpeg CVE-2026-8461 (PixelSmash): RCE via Media Files A heap out-of-bounds write in FFmpeg's MagicYUV decoder scores CVSS 8.8 and hits 9+ apps… Read more: https://www.navanem.com/news/ffmpeg-pixelsmash-cve-2026-8461-enables-rce-via-crafted-media-files-mqqwkgyv #Ffmpeg #Cve20268461 #Rce #MediaServer

    Post summary

    FFmpeg CVE‑2026‑8461 exposes a heap out‑of‑bounds write in the MagicYUV decoder, allowing remote code execution via crafted media files; the vulnerability scores CVSS 8.8.

    0003021
    5 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    FFmpeg の脆弱性 PixelSmash CVE-2026-8461:細工されたメディア・ファイルによる RCE の恐れ https://iototsecnews.jp/2026/06/23/critical-ffmpeg-vulnerability-lets-hackers-execute-remote-code-via-malicious-media-files/ この脆弱性 CVE-2026-8461 は、 FFmpeg の MagicYUV デコーダにおけるスライス高の計算処理の不備に起因します。具体的には、バッファ割り当てのサイズと実際のデコード・ロジックの不一致が生じ、不正な入力値による誤ったクロマプレーン計算が引き起こされます。これにより、本来のヒープ領域を超えて 1 行分のデータが書き込まれるオーバーフローが発生します。結果として、メモリ上の隣接する構造体の書き換えにより関数ポインタが不正に制御され、意図しないコマンドが実行可能な状態になります。ご利用のチームは、お気をつけください。 #CVE20268461 #FFmpeg #Vulnerability

    Post summary

    The article announces the new CVE-2026-8461 vulnerability in FFmpeg’s MagicYUV decoder, explains how a buffer overflow leads to remote code execution, but does not provide PoC code, exploit tools, or patch information.

    01001126
    501 followersView on X
  • 萤火@hey_akie
    Patch

    🥳 服务器目前版本已更新至 v4.6.2 本次更新包括: • 修复 Emoji、下拉菜单、高级界面、个人资料字段及 LDAP 登录等问题 • 更新 Docker 镜像中的 FFmpeg,修复严重安全漏洞 CVE-2026-8461 • 本站的 5000 字符上限继续保留 https://m.somincola.org/

    Post summary

    These release notes announce that the FFmpeg component in the Docker image has been patched to address CVE‑2026‑8461, but provide no PoC, exploit, or detailed technical data.

    0002063
    1.2K followersView on X
  • 睡不够喵@4i62h02h
    Disclosure

    CVE-2026-8461 FFmpeg Pixel Smash 1, it cannot be used to get root, it is a emote code execution (RCE) vulnerability 2, it needs matched version of ffmpeg with debug symbols and gdb to calculate the address, and ASLR needs to be disabled. 3, useful info https://nvd.nist.gov/vuln/detail/CVE-2026-8461

    Post summary

    The message provides technical details about CVE-2026-8461 in FFmpeg, describing it as an RCE that requires debug symbols and ASLR disabled, but it does not mention a PoC, exploit, or active exploitation.

    1000071
    172 followersView on X
  • Hexnode@thehexnode
    Active Exploitation

    This week’s What to Watch, Patch, and Secure series covers exploited vulnerabilities, enterprise data exposure, media pipeline risks, phishing campaigns, and infrastructure security concerns. 🔹 Cisco SD-WAN zero-day attacks CVE-2026-20245 was exploited after attackers gained access to Cisco Catalyst SD-WAN Manager, allowing root-level access through a crafted CLI upload workflow. https://www.hexnode.com/blogs/cve-2026-20245-cisco-ssd-wan-zero-day-attacks/ 🔹 PTC Windchill vulnerability added to CISA KEV CISA added CVE-2026-12569 to its KEV catalog after evidence of active exploitation involving persistent JSP web shells in Windchill environments. https://www.hexnode.com/blogs/ptc-windchill-vulnerability-added-to-cisa-kev/ 🔹 Nissan PeopleSoft data breach Nissan disclosed an employee data breach tied to its Oracle PeopleSoft environment, with potentially accessed data including employee contact, banking, tax, and identifier information. https://www.hexnode.com/blogs/nissan-data-breach-peoplesoft-zero-day-puts-hr-identity-data-at-risk/ 🔹 Tata Electronics cyberattack Tata Electronics confirmed a cybersecurity incident affecting parts of its IT systems, while an extortion group claimed to have published allegedly stolen company data. https://www.hexnode.com/blogs/tata-electronics-cyberattack-manufacturing-data-extortion/ 🔹 Xsolis data breach A targeted phishing attack led to unauthorized access at Xsolis, exposing sensitive health and identity information belonging to nearly 1.4 million people. https://www.hexnode.com/blogs/xsolis-data-breach/ 🔹 Cisco Unified CM vulnerability exploitation CVE-2026-20230 affects Cisco Unified CM and Unified CM SME when WebDialer is enabled, with public reporting showing exploitation attempts using file-write payloads. https://www.hexnode.com/blogs/cisco-unified-cm-vulnerability-exploited-why-voip-infrastructure-needs-patch-urgency/ 🔹 FFmpeg PixelSmash vulnerability CVE-2026-8461 is a high-severity FFmpeg flaw that can be triggered through crafted video files, putting media-processing pipelines and applications that rely on FFmpeg at risk. https://www.hexnode.com/blogs/ffmpeg-pixelsmash-cve-2026-8461-why-enterprises-should-patch-media-pipelines-fast/ 🔹 Edgecution malware campaign Edgecution abuses Microsoft Edge Native Messaging to connect a malicious browser extension with a Python backdoor, turning browser activity into a path for host-level command execution. https://www.hexnode.com/blogs/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge/ 🔹 Node.js implant phishing campaign Hotels across Europe and Asia are being targeted with photo-themed ZIP files that use disguised Windows shortcuts, PowerShell, and a local Node.js runtime to execute the TonRAT implant. https://www.hexnode.com/blogs/node-js-implant-phishing-campaign-targets-hotels-with-photo-zip-files/ Stay informed, prioritize what matters, and strengthen your security posture one week at a time.

    Post summary

    The post highlights several CVEs with clear evidence of ongoing exploitation—root-level access in Cisco SD‑WAN and persistent JSP shells in PTC Windchill—yet it does not provide PoC code, patches, or false‑positive claims.

    10000251
    17.6K followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    ⚠️ ثغرة حرجة في مكتبة فيديو شائعة تتيح تنفيذ أوامر على خوادم جيلي فين عبر ملف فيديو مزور. المعرّف : CVE-2026-8461 درجة الخطورة : 8.8 - High المكوّن : FFmpeg MagicYUV decoder الحل : Upgrade to FFmpeg 8.1.2 #CVE #FFmpeg #CyberSecurity #CVE202608461

    Post summary

    The post highlights a critical CVE (CVE‑2026‑8461) affecting FFmpeg’s MagicYUV decoder, notes that malicious video files can trigger command execution on Jellyfin servers, and recommends applying the FFmpeg 8.1.2 upgrade.

    01000120
    40.0K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical FFmpeg MagicYUV vulnerability (CVE-2026-8461) allows attackers to achieve remote code execution via crafted media files. Patch systems quickly. #FFmpeg #Vulnerability #CyberSecurity #CVE20268461 #PixelSmash https://securityonline.info/ffmpeg-magicyuv-vulnerability https://t.co/J3snV5Pn4I

    Post summary

    CVE-2026-8461 is a critical remote code execution flaw in FFmpeg’s MagicYUV, and users are urged to apply the available patch promptly.

    00001566
    12.4K followersView on X
  • けいじいじ| AI様のHaaSくらいにはなりたい@kei_tone
    General

    ❌:何もしてないのに壊れた! ⭕️:適切なセキュリティ対策予算を組まないをした ⭕️:脆弱性報告を自分ごとだと思わないをした #PixelSmash #CVE-2026-8461 https://t.co/NHUSD8CgxQ

    Post summary

    The tweet laments a system failure and references CVE-2026-8461 but offers no technical, exploitation, or mitigation information.

    00010104
    192 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #FFmpeg's #MagicYUV decoder contains a critical #vulnerability that may result in denial of service (#DoS) or remote code execution (#RCE) when processing a maliciously crafted media file. #CVE-2026-8461 CVSS: 8.8 #PixelSmash. Time to #Patch #Patch #Patch

    Post summary

    The tweet alerts to a serious CVE‑2026‑8461 flaw in FFmpeg’s MagicYUV decoder that can lead to DoS or RCE, emphasizing the need to apply a patch.

    01000344
    7.2K followersView on X
  • NCX Group Security@ncxgroup
    Disclosure

    A 50 KB video file shouldn't be able to hijack your media server. But PixelSmash (CVE-2026-8461) makes it possible. This high-severity FFmpeg flaw (CVSS 8.8) can enable RCE or DoS via a crafted clip—putting hundreds of dependent apps at risk. Read more: https://f.mtr.cool/ohhideuztf

    Post summary

    The post announces a high‑severity FFmpeg vulnerability (CVE‑2026‑8461) that can enable RCE or DoS via a crafted 50 KB video, but it does not provide PoC, exploit, or active exploitation details.

    0000153
    9.9K followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Disclosure

    🚨 BREAKING: you don't have to click anything. you don't have to open any file. you don't even have to be at your keyboard. A hacker just needs to get one video file near your system, and it's over. 💀 Meet PixelSmash CVE-2026-8461. Disclosed yesterday. critical. widespread. real. 🧵 here's what's happening and who's affected.

    Post summary

    The post announces the discovery of CVE-2026-8461 as a critical, widespread flaw that can be triggered by placing a video file near a system, but it offers no technical details, PoC, or patch information.

    1000081
    9.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    CVE-2026-8461 (CVSS 8.8): heap OOB write in FFmpeg's MagicYUV decoder enables RCE via a single 50 KB media file upload, hitting Jellyfin, Nextcloud, Emby, Immich, OBS, and AI/ML pipelines. - CVE-2026-8461 lives in libavcodec/magicyuv.c. When slice_height is odd (attacker-controlled via bitstream), ceiling-rounded chroma shifts accumulate an extra row per slice past the allocated buffer. With coded_height=32 and slice_height=31, the decoder writes 640 attacker-controlled bytes one full row beyond the Cb chroma plane, landing directly on the AVBuffer struct FFmpeg allocates immediately after pixel data. - Exploitation overwrites http://AVBuffer.free with system() and AVBuffer.opaque with a shell command pointer. When av_frame_unref fires during normal frame cleanup, the hijacked indirect call executes the attacker's command before the process crashes. JFrog demonstrated a reverse shell on Jellyfin 10.9 (jellyfin-ffmpeg 7.1.3) via automatic library scan and on Nextcloud via the Movie preview provider, both triggered by uploading a single crafted AVI with zero authentication. ASLR was disabled for the RCE demo; without ASLR bypass the primitive reliably delivers DoS on every tested target. - The torrent vector is zero-click: a malicious AVI dropped into Jellyfin's watched media folder triggers ffprobe automatically. #DFIR_Radar

    Post summary

    The post provides a detailed technical breakdown of a heap OOB write in FFmpeg’s MagicYUV decoder that enables remote code execution, along with a proof‑of‑concept demonstration of a reverse shell on several services.

    10000247
    1.7K followersView on X

Explore more